2vulptfpoov5djahqlskqza5v3itx3k2byj7zir5t3m3p2ann46a[.]g8way[.]io
2vulptfpoov5djahqlskqza5v3itx3k2byj7zir5t3m3p2ann46a.g8way.io — Belum terverifikasi. Jenis penipuan: Fake Airdrop. Ringkasan bukti: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker); CF Radar malicious; PhishDestroy score 97/100. Registrar: Key-Systems.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain 2vulptfpoov5djahqlskqza5v3itx3k2byj7zir5t3m3p2ann46a.g8way.io was observed resolving to the IP address 172.67.73.220, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are dexter.ns.cloudflare.com and ziggy.ns.cloudflare.com, confirming that the site was hosted behind Cloudflare’s CDN. The site was flagged by PhishDestroy and appears on one external security blocklist, indicating that at least one downstream security product has taken action against it. VirusTotal analysis shows that 14 of 95 scanning engines flagged the domain, providing independent confirmation of malicious intent. The TLS certificate presented by the server is issued by Google Trust Services under the WE1 root, which is typical for Cloudflare‑proxied sites and does not mitigate the underlying threat.
Reputation services assign extremely low scores: Scamadviser rates the domain 1/100 and Gridinsoft 0/100, reflecting a high likelihood of abuse. Registration data reveals the domain was created on 28 January 2023 through Key‑Systems GmbH, a registrar commonly used for both legitimate and illicit registrations. Automated analysis identified the use of Node.js, Envoy, Express, and Cloudflare as the underlying technology stack, a combination often leveraged to serve phishing kits efficiently. The specific kit detected is labeled “Airdrop Scam,” which is typically employed to lure victims with promises of free cryptocurrency distributions and harvest credentials or private keys.
The current operational status is offline, and no live HTTP response or page title is available for further content inspection. Uncertainty remains regarding any residual infrastructure that may be re‑activated, as well as the exact content that was served before takedown. Defenders should continue to block the domain and its associated IP, monitor for re‑appearance of similar subdomains under the g8way.
Sinyal Keamanan
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 4 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comAnalisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive